CVE-2026-7826: fallo de gravedad alta en FalkorDB
Heap out-of-bounds read in FalkorDB BufferSerializerIOv2_ReadBuffer via crafted RDB
Publicada el
18Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
FalkorDB · FalkorDBCVEs relacionadas — FalkorDB
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-107911HIGHType confusion in FalkorDB GRAPH.QUERY via the --bolt argumentEPSS —CVE-2026-107910CRITICALAuthentication bypass in FalkorDB Bolt endpoint via fail-open AUTH probe error handlingEPSS —CVE-2026-107909HIGHPre-authentication heap out-of-bounds write in FalkorDB Bolt WebSocket frame handling via unbounded payload lengthEPSS —CVE-2026-107908CRITICALPre-authentication heap out-of-bounds write in FalkorDB Bolt BoltReadHandler via RESET messageEPSS —CVE-2026-7827CRITICALStack-based buffer overflow in FalkorDB _RdbLoadEntity via unbounded property count in crafted RDBEPSS —CVE-2026-5759CRITICALDouble free and use-after-free in FalkorDB RdbLoadDeletedNodes allows remote code execution via crafted RDBEPSS —